Skip to main content
TCJ

Crypto

The UAE Crypto Travel Rule: Practical Compliance for VASPs

UAE virtual asset firms need more than a Travel Rule messaging tool. This practical guide explains thresholds, customer data, VASP checks, unhosted wallets, monitoring, exceptions and audit readiness.

By Mandeep Masoun·Published ·Updated ·11 min read
The UAE Crypto Travel Rule: Practical Compliance for VASPs
The UAE Crypto Travel Rule: Practical Compliance for VASPs

The UAE Crypto Travel Rule: Practical Compliance for VASPs

Key takeaways

  • AED 3,500 is a significant UAE compliance threshold, but it should not be treated as a blanket exemption for smaller crypto transfers.
  • Travel Rule compliance should connect KYC, counterparty due diligence, sanctions screening, blockchain monitoring, exceptions and record keeping.
  • Unhosted-wallet transfers require a defined risk-based control process rather than the same workflow used for regulated VASP counterparties.
  • A software provider can facilitate Travel Rule messaging, but the regulated firm remains responsible for its compliance framework.
  • UAE firms should map federal requirements and their own supervisory rulebook before configuring operational controls.

What is the Crypto Travel Rule?

The Crypto Travel Rule is an AML/CFT control requiring specified information about the originator and beneficiary to accompany, or remain associated with, relevant virtual asset transfers. Its purpose is to improve traceability and make it more difficult for virtual asset transfers to move anonymously through regulated financial channels.

FATF applies payment-transparency principles to virtual assets and VASPs through its standards. FATF also revised Recommendation 16 in 2025 to clarify responsibilities and standardise parts of payment information requirements. Those revised international changes are scheduled to take effect by the end of 2030, so UAE businesses should distinguish future FATF implementation from the UAE rules that apply to them now.

A Travel Rule control is only as reliable as the customer, counterparty and transaction controls around it; sending a compliant data message does not resolve weak KYC or unexplained wallet activity. — KPM Global Services UAE consultant observation

How does the Travel Rule apply to UAE virtual asset firms?

UAE businesses should first identify the regulator, licence and activities governing each transfer rather than treating the country as having one uniform virtual asset rulebook.

For a VARA VASP, the Compliance and Risk Management Rulebook expressly requires compliance with Federal AML-CFT Laws and adds VARA's Travel Rule minimum standards. VARA regulates virtual asset activities across Dubai's mainland and free zones, except within the Dubai International Financial Centre.

Within ADGM, the FSRA AML Rulebook contains specific provisions for transfers of Virtual Assets and Fiat-Referenced Tokens. The current rulebook requires relevant transfer information to remain associated with a transfer while it is under the firm's control, together with monitoring, appropriate counterparty due diligence and records sufficient to reconstruct transfers.

For compliance teams, this means a regulatory mapping exercise should come before system configuration. The firm needs to know which federal requirements, supervisory rules and internal risk standards govern each transfer scenario.

When does the AED 3,500 threshold matter?

AED 3,500 is an important threshold, but UAE VASPs should not configure their systems as though every transaction below this figure falls outside Travel Rule or AML controls.

The federal UAE Virtual Assets Travel Rule refers to daily aggregated amounts of AED 3,500 or more for specified identity-verification requirements. For transfers below the daily aggregated amount, required data obligations can still apply, although verification treatment differs unless there is suspicion concerning criminal activity.

The UAE's current federal AML executive regulations also require VASPs to apply customer due diligence to occasional transactions amounting to or exceeding AED 3,500, whether completed as one transaction or through several transactions that appear to be linked.

VARA separately states that, before initiating a virtual asset transfer exceeding AED 3,500, a VASP must obtain and hold the required originator and beneficiary information. VARA also requires monitoring for transactions or series of transactions designed to circumvent regulatory thresholds.

The practical control is therefore not “under AED 3,500 means no checks.” Systems should identify linked transactions, aggregation, unusual splitting patterns and other behaviour that may indicate threshold avoidance.

Example 1: A fictional Dubai VASP receives instructions from the same customer for several smaller withdrawals to related wallet addresses during one day. Even where each withdrawal appears modest on its own, the compliance workflow should consider aggregation, customer behaviour and whether the transactions appear deliberately structured.

What information should a Travel Rule process capture?

The information required depends on the applicable rules, but a Travel Rule data model should begin with accurate originator and beneficiary information that can be reconciled with the firm's verified customer records.

Under VARA's minimum requirements, originator information includes the name, account number or VA wallet address, and residential or business address. Minimum beneficiary information includes the beneficiary's name and account number or VA wallet address, subject to additional requirements under Federal AML-CFT Laws.

ADGM's framework defines a more detailed set of relevant transfer information. It includes the originator's full name, account number, residential or business address, and an additional identifier such as a national identity number, customer identification number, or date and place of birth, together with beneficiary information.

A practical UAE compliance team should therefore maintain a clear internal data requirement for each transfer type and regulatory perimeter rather than relying on one generic withdrawal form.

How should a UAE VASP build its Travel Rule workflow?

A workable process connects Travel Rule requirements to existing Financial crime and operational controls. Each transfer should pass through defined stages before assets are released or made available.

1. Identify the transfer type

The firm should determine whether it is acting for the originator or beneficiary, whether another VASP is involved, whether the transfer involves an unhosted wallet, and which jurisdictions and regulators are relevant.

Correct classification determines what information must be collected and what additional due diligence or escalation may be required.

2. Reconcile transfer data with customer due diligence

Travel Rule information should normally be drawn from or checked against reliable KYC and CDD records.

Names, addresses, identifiers and wallet details that conflict with the verified customer profile should not simply pass because mandatory system fields have been completed. Material discrepancies should enter an exception or review process.

3. Conduct counterparty VASP due diligence

A VASP-to-VASP transfer also creates counterparty risk. VARA requires risk-based due diligence before entering into a transaction with a counterparty VASP, with further review where heightened risk is identified.

Depending on the risk, a firm may consider regulatory status, jurisdiction, ownership, AML controls, Travel Rule capability, sanctions exposure, security arrangements and whether required information can be exchanged reliably.

4. Transmit information securely

Travel Rule information contains personal and compliance-sensitive data. The firm's solution should preserve confidentiality, integrity and retrievability while keeping the identifying information connected to the relevant virtual asset transfer.

Using an external protocol or technology provider can support this process, but it does not transfer the VASP's regulatory responsibility to the software provider.

5. Screen and monitor the transaction

Travel Rule data should feed into the broader AML control environment rather than sit in an isolated system.

The firm should consider customer risk, beneficiary information, counterparty exposure, wallet history, sanctions results, blockchain activity, transaction patterns and other relevant indicators. VARA requires transaction screening against applicable sanctions frameworks, while ADGM's rules require monitoring designed to identify missing information and suspicious VA/FRT activity.

6. Define what happens when information is missing

A written exception policy is essential. Receiving VASPs under the federal Travel Rule must have risk-based procedures addressing transfers that arrive without required originator or beneficiary information, including circumstances in which a transfer may be rejected, permitted, delayed or otherwise handled.

The policy should identify who reviews an exception, what additional information is requested, when the MLRO becomes involved, when a transfer is restricted and when suspicious transaction reporting should be considered.

How should unhosted wallets be handled?

Unhosted or self-custody wallets require a different control approach because the other side of the transfer may not be a regulated institution capable of exchanging Travel Rule data.

The federal UAE Travel Rule contains dedicated provisions for unhosted-wallet transfers, while VARA requires VASPs to consider the risks of dealing with non-obliged entities such as unhosted VA wallets. ADGM's definition of a VA/FRT transfer also expressly includes transfers to or from an unhosted wallet.

Depending on the circumstances, practical controls may include establishing wallet ownership or control, documenting the transfer purpose, reviewing source of funds, assessing blockchain history and applying enhanced monitoring where risk justifies it.

Example 2: A fictional Abu Dhabi virtual asset business receives a large customer transfer from a newly disclosed self-custody wallet. Instead of treating the blockchain transaction as sufficient evidence, the compliance team requests supporting information, checks the wallet's history and records why the transaction was accepted or escalated.

UAE firms should also be aware that the CBUAE's Virtual Assets Travel Rule states that a UAE VASP must not execute a virtual asset transfer of a Privacy Token because of its potential to obscure transaction details.

What common Travel Rule compliance mistakes should firms avoid?

Common weaknesses tend to appear at the operational level rather than in the policy document itself.

  • Treating AED 3,500 as a complete exemption without considering aggregation, linked activity or other applicable obligations.
  • Allowing Travel Rule information to differ from verified KYC records without investigation.
  • Relying entirely on a third-party technology provider without internal oversight.
  • Failing to verify or risk-assess counterparty VASPs.
  • Automatically accepting incoming transfers with incomplete information.
  • Applying minimal controls to self-custody or unhosted wallets.
  • Keeping blockchain transaction records but not the compliance decisions behind them.
  • Using one workflow across different UAE regulatory regimes without checking the applicable requirements.
  • Failing to test exception handling before a technology or communications failure occurs.
  • Treating Travel Rule compliance as an IT project rather than an AML governance responsibility.

What records should be available for an audit or regulatory review?

A strong Travel Rule framework should allow the compliance team to reconstruct what happened during a selected transfer without relying on individual staff members' memory.

For a sampled transaction, businesses should consider retaining or being able to retrieve:

  • customer and beneficiary identification information;
  • KYC and CDD evidence;
  • sending and receiving wallet addresses;
  • blockchain transaction references;
  • counterparty VASP information and due diligence;
  • Travel Rule messages and transmission records;
  • sanctions and screening results;
  • transaction-monitoring alerts;
  • source-of-funds or enhanced due-diligence evidence where applicable;
  • missing-data enquiries;
  • compliance exceptions and approvals;
  • MLRO escalations where relevant; and
  • the final transaction decision.

VARA requires specified AML/CFT records to be retained for no less than eight years and may require information concerning the effectiveness of Travel Rule controls. ADGM's AML framework similarly requires records sufficient to reconstruct relevant VA/FRT transfers.

What should UAE firms prepare before reviewing their Travel Rule controls?

A practical preparation checklist includes:

  • current VASP licence and authorised activity details;
  • federal and regulator-specific AML policies;
  • customer KYC and CDD procedures;
  • Travel Rule policy and operating procedures;
  • originator and beneficiary data-field requirements;
  • transaction aggregation and threshold logic;
  • counterparty VASP due-diligence files;
  • approved and restricted counterparty criteria;
  • unhosted-wallet procedures;
  • sanctions and blockchain-monitoring controls;
  • missing-information and exception procedures;
  • Travel Rule technology-provider agreements;
  • information-security and data-transmission controls;
  • record-retention settings;
  • staff and MLRO escalation procedures; and
  • recent testing, audit findings and remediation records.

How can KPM Global Services UAE assist?

KPM Global Services UAE can support businesses reviewing the operational structure around UAE AML and virtual asset compliance, depending on the firm's licence, regulator and activities.

Support may include reviewing existing procedures, documenting compliance workflows, mapping control responsibilities, identifying documentation gaps, preparing internal control checklists, improving audit readiness and coordinating Travel Rule processes with wider Accounting, Financial and compliance governance.

For regulated virtual asset activities, specialist legal or regulatory interpretation may also be required. Businesses should ensure their advisers and internal teams work from the requirements applicable to the specific licence and transfer arrangement.

The Travel Rule is best treated as an end-to-end AML control. A UAE VASP that can transmit the correct information but cannot explain the customer, counterparty, wallet risk, monitoring outcome or exception decision may still have a material compliance weakness.

Businesses should periodically reassess their policies, technology, counterparty arrangements and operational controls as federal requirements and supervisory rules develop. FATF's revised Recommendation 16 also creates a longer-term international implementation issue that firms may need to monitor ahead of its scheduled 2030 effectiveness.

This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.

Questions and answers

Q: What is the UAE Crypto Travel Rule?

A: The UAE Crypto Travel Rule requires covered virtual asset firms to obtain, retain and appropriately handle identifying information relating to originators and beneficiaries of relevant virtual asset transfers. The exact obligations depend on federal requirements and the firm's supervisory regime.

Q: Is AED 3,500 the Travel Rule threshold in the UAE?

A: AED 3,500 is a significant threshold, but it is not a blanket exemption below that amount. Federal rules address daily aggregated amounts and linked activity, while VARA imposes additional minimum requirements for transfers exceeding AED 3,500.

Q: Does the UAE Travel Rule apply to unhosted or self-custody wallets?

A: UAE regulatory frameworks specifically address unhosted-wallet transfers. Firms should apply procedures appropriate to the risk, which may include additional information, wallet assessment, source-of-funds review and enhanced transaction monitoring.

Q: Can a UAE VASP accept a crypto transfer with missing Travel Rule information?

A: The answer depends on the applicable rules and the risk assessment. Federal requirements require receiving VASPs to maintain risk-based procedures for incomplete transfers, which can include rejecting, permitting, delaying or otherwise escalating a transaction.

Q: Does Travel Rule software make a UAE VASP compliant?

A: No. Technology can support data collection, secure messaging, counterparty identification and record keeping, but the VASP remains responsible for its policies, customer controls, AML monitoring, exception decisions, governance and regulatory compliance.

Our services

What we can do for you

The Consulting Journal publishes analysis—and we also deliver commercial work: publishing, brand expansion, promotion, SEO, influencers, UAE setup, VAT, accounting, and consultations. Open a service to enquire.

See all services and send a request